30 people and no security person
It is not free. At 30 people the cost shows up as roughly 10 to 20 hours a month of your most expensive engineering time, plus deal delay, and it is invisible because nobody invoices you for it.
A 30 person Canadian startup with nobody owning security still absorbs roughly 10 to 20 hours a month of senior technical time. At a loaded cost of $90 to $130 CAD an hour that is $11,000 to $31,000 CAD a year, and it never appears in a budget line. That is the visible half. The other half is deal delay, and one enterprise contract pushed a quarter is usually larger than every other number on this page.
Under 25 people the arithmetic says do nothing, which is the position on whether a startup needs a vCISO yet. The range that matters is 25 to 80, where the cost is real and the answer is not obvious.
Where do the hours actually go?
Nobody at 30 people sits down to do security. The time goes in fragments, which is why it is never counted.
| Work | Hours per year | Who it usually lands on |
|---|---|---|
| Customer security questionnaires, 4 to 8 a year | 30 to 70 | The technical founder, or a small team's VP engineering |
| Vendor security reviews you run on your own suppliers | 10 to 20 | Whoever signed the contract |
| Access reviews, joiners and leavers, done by hand | 15 to 30 | Operations or the first engineer |
| Cyber insurance application and renewal | 8 to 16 | Finance, with three engineering interruptions |
| Responding to a vulnerability disclosure or a scan result | 20 to 60 | Engineering, unplanned |
| Writing or updating policies when a customer asks | 20 to 50 | Whoever has the least to do that week, which is nobody |
| Meetings about all of the above | 20 to 40 | Three people at once |
| Total | 123 to 286 hours | Loaded cost $11,000 to $31,000 CAD |
The bend is the useful part. Between 20 and 50 people the load roughly triples, in the same quarter the company is trying to close its first large customers. The hours come out of the two people with the least slack, so the cost lands as slipped product dates, not as a security failure.
What else does it cost, besides hours?
- Deal delay
- The measurable one. A security review that takes six weeks instead of two because nobody owns the response pushes revenue into the next quarter. On a $200,000 CAD annual contract, a one quarter slip is $50,000 of recognised revenue moved, and sometimes the deal itself.
- Answers you cannot support
- Questionnaires answered under time pressure by someone guessing produce contractual commitments nobody tracks. This surfaces at renewal, at an incident, or when the customer exercises an audit right.
- Insurance priced on an incomplete application
- Cyber insurance underwriting is a control questionnaire with a premium attached. Applications filled in defensively, or with a no where an honest yes was available, cost real money at renewal.
- The decision nobody makes
- The largest cost at this size is not work done badly, it is decisions deferred: which framework to target, whether to move data into Canada, whether to accept a contract clause. Each one gets more expensive the later it is made, and none of them has an owner.
What does fixing it cost?
The right route depends on whether you have a recurring job or a one-time gap.
| Option | Year one, CAD | What it actually gets you |
|---|---|---|
| Keep absorbing it | $11,000 to $31,000 in hidden time | No decisions made, no artifacts, and the load rises with headcount |
| Assign it internally, with a budget and a day a week | $20,000 to $35,000 in reallocated time | An owner, if you protect the time. This is the right answer more often than this site's business model would suggest |
| One-off assessment and policy set | $5,000 to $15,000 | A written starting position you own. No ongoing ownership |
| Fixed-scope project, such as readiness for a specific customer | $15,000 to $40,000 | A defined outcome with an end date and an acceptance test |
| Advisory retainer, 8 to 16 hours a month | $36,000 to $72,000 | A standing owner between audits. Worth it once the job is recurring |
| Hire a security engineer | $140,000 to $210,000 loaded | Hands to do the work, and no seniority to make the risk decisions |
The second row is cheaper than the fifth and is often the right answer. A senior engineer with one day a week, a budget and explicit authority beats a retainer bought to avoid the conversation. It fails when the person has no slack, which is the case in most 30 person companies. Who should own security when there is no CISO works through the internal version, and your first security hire covers whether the sixth row should ever come before the fifth.
The number to run yourself
Take the two people who absorb this work, multiply their loaded hourly cost by the hours in the first table, and put it beside a $4,000 CAD monthly retainer. If the retainer looks expensive, you are probably at the low end of the hours and should not buy one yet. The ROI calculator runs the same comparison with your own figures, and the hours calculator sizes the retainer.
Work out what this is costing you
Tell us your headcount, how many customer security reviews you have had this year, and who is currently absorbing them. We will tell you whether the answer is a project, a retainer or nothing yet.
Get matchedCommon questions
We are 30 people and nothing has gone wrong. Is this really costing us anything?
Yes, in time, and the time is being spent by the two people you can least afford to interrupt. Whether that matters depends on whether you are selling to businesses that run security reviews. A 30 person company selling to other small companies genuinely can defer this. A 30 person company with two enterprise logos in the pipeline is already paying, in slipped deal dates.
Is a compliance platform cheaper than a person?
It is a different purchase. A platform at $8,000 to $30,000 CAD a year automates evidence collection and monitoring, which is genuinely useful once you have controls to monitor and an audit to feed. It does not decide anything, it does not answer a customer call, and at 30 people with no program running it produces a dashboard of red items nobody owns. Buy the owner first, then the tool.
What headcount is the real threshold?
Headcount is the worst available proxy and the one everyone uses. The better triggers are: more than three customer security reviews a year, a contract with security obligations in it, regulated data, or an engineering team large enough that the founder can no longer review every change. Any two of those together matter more than crossing 50 people.
Could we just ask our managed IT provider to own security?
They can own controls and they cannot own the risk decision, because they are a supplier and the decision has to be accepted by your company. A managed provider is a reasonable answer for endpoint management, patching and backups at this size. It is not an answer for what you tell a customer, what you accept in a contract, or which framework you target.
Our engineering lead already handles security. Is that a problem?
It is common and it works for a while. Two things break it: the person who builds the system is also assuring it, which an auditor or an insurer will eventually name, and the work has no protected time so it happens last. When your engineering lead is doing security badly covers how to tell which of those you are in without making it personal.